Lack of Authorization and Stored XSS Via Translation Abuse
CVE-2023-41791
8.4HIGH
What is CVE-2023-41791?
A Cross-Site Scripting (XSS) vulnerability in Pandora FMS allows users with low privileges to inject malicious JavaScript code through a translation string. This attack vector compromises the integrity of system configuration files and poses significant risks to the application's security. Organizations using affected versions, ranging from 700 to 773, need to promptly address this vulnerability to prevent potential exploitation.
Affected Version(s)
Pandora FMS all 700 <= 773
